vulnerability

FreeBSD: VID-57FACD35-DDF6-11E6-915D-001B3856973B (CVE-2017-5333): icoutils -- check_offset overflow on 64-bit systems

Severity
7
CVSS
(AV:N/AC:M/Au:N/C:P/I:P/A:P)
Published
Jan 3, 2017
Added
Jan 19, 2017
Modified
Nov 11, 2019

Description

Details for this vulnerability have not been published by NIST at this point. Descriptions from software vendor advisories for this issue are provided below.


From VID-57FACD35-DDF6-11E6-915D-001B3856973B:




Choongwoo Han reports:



An exploitable crash exists in the wrestool utility on 64-bit systems


where the result of subtracting two pointers exceeds the size of int.




Solution

freebsd-upgrade-package-icoutils
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.